CVE-2022-20083: Critical severity Google Android vulnerability
In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00803883; Issue ID: MOLY00803883.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20083?
CVE-2022-20083 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2022-20083?
To fix CVE-2022-20083, apply the security patch identified by Patch ID: MOLY00803883.
What products are affected by CVE-2022-20083?
CVE-2022-20083 affects various versions of Google Android and MediaTek LR series modems.
Is user interaction required to exploit CVE-2022-20083?
No, user interaction is not needed for exploitation of CVE-2022-20083.
What could happen if CVE-2022-20083 is exploited?
Exploitation of CVE-2022-20083 could lead to remote code execution, potentially allowing an attacker to take control of the affected device.